Feith is FedRAMP Moderate Authorized Read the release
Feith
Higher education

One platform for the campus record.

The Feith Platform for Higher Education runs admissions, financial aid, the registrar, sponsored research, and the eight other offices that own records, on the same architecture that manages federal agencies' permanent records. Every access writes to one append-only audit log.

12
Campus offices on one platform, admissions through student health.
6
Compliance regimes configured on one platform, not six point systems.
47 yrs
Building federal records technology since 1979.
45 days
The FERPA access window, tracked as a case from request to release.

FERPA · GLBA · HIPAA · NIST 800-171 · state public records · Title IX, all on one platform. Records engine built to DoDM 8180.01, the current DoD standard, with DISA-JITC testing heritage under the retired DoD 5015.02 · FIPS 140-3 encryption · FedRAMP Moderate authorized on the federal side · built and owned in Fort Washington, PA.

Higher-ed records in 2026

Six regimes. Twelve offices. One records officer holding the bag.

FERPA governs the student record. GLBA governs the aid file. NIST 800-171 covers anything CUI that arrives with a federal grant. State law and Title IX layer their own rules on top. And the records don't sit in one system.

  • FERPA the student record
  • GLBA Safeguards the financial-aid file
  • HIPAA campus health, where it applies
  • NIST 800-171 CUI from federal research
  • State public records open-records requests
  • Title IX investigation evidence

They live in Banner, PeopleSoft, Workday, M365, Google Workspace, file shares, and the paper folders some offices still keep, and the records officer is responsible for all of it. Feith takes responsibility for the records the moment they exist. Capture normalizes the metadata, the vault holds the authoritative copy, the audit log records every access, and retention runs against each office's schedule.

Students raising their hands in a university lecture hall
The lecture hall is where the record begins, and Feith governs it from the day it's created to the day it's disposed.
Twelve offices · five modules · one platform

Every office on campus owns records. Feith covers every office.

Twelve departmental workflows, organized into five family modules, each on the same vault, identity layer, and audit log, each shipping with the document types, workflows, and retention rules the family actually uses.

Student records

Admissions · Financial Aid · Registrar / Transcripts · Bursar · Graduate School

The offices that own the official student record. Applications and transcripts arrive from Slate, Common App, and the SIS; award files run through verification and appeals; transcripts release inside the 45-day FERPA window.

Compliance FERPA · directory-information rules · GLBA Safeguards · Title IV evidence · NSLDS / COD retention.

Research & sponsored programs

Sponsored Programs · Research

Grant files, IRB and IACUC records, and the CUI that arrives with a federal research contract, all held in one campus vault.

Compliance NIST 800-171 · CMMC · ITAR · EAR · NIH and NSF retention.

People & faculty

HR / Faculty · Advancement / Alumni

Personnel files, tenure dossiers, search-committee records, and faculty contracts, plus gift records, donor files, and planned-giving documentation, separated from FERPA-protected records at the access layer where policy requires it.

Compliance EEOC · tenure schedule · CASE reporting standards · IRS substantiation.

Legal & public records

General Counsel / Public Records · Title IX / Conduct

Open-records requests, subpoena response, and e-discovery, alongside Title IX investigation files that need separated roles and a preserved evidence chain.

Compliance State public-records law · current Title IX requirements · Clery Act overlap · litigation hold.

Student health

Student Health (HIPAA-adjacent)

Counseling, health-services, vaccination, and accommodation records, held as FERPA treatment records, which the HIPAA Privacy Rule expressly excludes from protected health information, with HIPAA reaching the health center's non-student patients and ADA accommodation records kept separate.

Compliance FERPA treatment records · HIPAA for non-student patients · ADA accommodation rules.
FERPA, by design

FERPA is an architecture decision, built in from the start.

Feith treats FERPA as a structural requirement. Every access to a student record writes to an append-only log, the 45-day access window is a tracked workflow, and the school-official exception is logged with the determination that justified it.

  • Every read, write, and disclosure of a FERPA-covered record writes to the append-only audit log: user, role, action, timestamp, record ID, and reason code.
  • Directory-information opt-outs apply at the field level: a student can opt out of one field and stay opted in elsewhere.
  • FERPA asks for reasonable methods to keep school officials inside their legitimate educational interest. Feith logs the determination at the moment of access, so auditors see the basis, not just the access.
  • Disclosures under FERPA exceptions (subpoena, health-and-safety emergency, accrediting organization) write to a separate channel with the legal basis attached. AI can classify and route intake faster; the disclosure decision stays with the records officer.
What one audit entry records
User · role
Who touched the record
Action
View · update · disclose
Reason code
Required, e.g. transcript request
Stamp
Timestamp + record ID, immutable
Append-only · hash-verified · forwarded to your SIEM.
45-day access window: a tracked case

The clock starts on the request. The package returned to the requester is itself recorded.

Sponsored research · CUI · ITAR · CMMC

The research office that holds federal contracts.

Federally-funded research carries federal records obligations: CUI markings, NIST 800-171 controls, ITAR and EAR export controls, CMMC posture for DoD work. Feith handles them on the same platform that handles your registrar's transcripts. The research office stops standing up parallel systems to satisfy compliance.

  1. 1
    Marked at capture
    The CUI marking is applied on intake and travels with the record.
  2. 2
    Enforced at access
    Checked at the user, record, and project level on every read; U.S.-person status verified.
  3. 3
    Audited to a control
    Each access ties to a NIST 800-171 control: your evidence, ready for assessment.
  • CUI is marked at capture, propagated through the workflow, and enforced at access.
  • Audit-log evidence supports your own NIST 800-171 assessment, so the record of who touched controlled research data is already assembled.
  • ITAR and EAR access restrictions are enforced at the user, record, and project level.
  • CMMC-relevant controls run on the single-tenant deployment: NIST 800-171 safeguards for CUI, enforced at access and evidenced in the audit log.
  • Sponsored-programs systems like Cayuse, Kuali, and InfoEd are integrated as capture sources during the project, so grant files flow into the same vault.
General counsel · public records · Title IX

The records workflows under the most scrutiny. Both run on Feith.

State public-records requests arrive with a clock attached. Title IX files have to be retained, redacted, disclosed selectively, and held for years. Both run on the same vault, with the same exemption logic and redaction tooling as Feith's federal FOIA Workbench.

The foundation underneath

One identity. One audit log. Every record, every system.

Feith runs on the identity layer your campus already uses, and runs lifecycle and audit across records wherever they live, without forcing a migration.

One identity layer

SAML, Shibboleth, AD / LDAP, and MFA: the login your campus already uses, with role attributes derived from the SIS. Need-to-know access is enforced per record, per field, per workflow step.

One audit log

Append-only, hash-verified, anti-tamper, with Splunk / SIEM forwarding. The same audit architecture built for federal records — DoDM 8180.01 today, DISA-JITC tested against DoD 5015.02 from 2002 until that standard was retired — holds your campus access log too.

One vault, every source system

Connectors capture from M365, Google Workspace, file shares, and the SIS, and a governed copy lands in the vault with its metadata intact. Your teams keep working in the tools they already use; retention, holds, disposition, and audit run against the authoritative copy in the vault.

Migration from your current ECM

Move from the ECM you have today to the platform you need tomorrow.

Most campuses come from OnBase, Banner Document Management, Laserfiche, Perceptive Content, or a homegrown stack. The migration runs in three phases, one at a time, so the path stops being all-or-nothing.

  1. 1

    Capture-only deployment

    Records flow into Feith from your existing systems while your incumbent ECM keeps running. Identity and audit consolidate first; the new vault carries everything that arrives after go-live without touching the legacy archive.

    No system retires in this phase.

  2. 2

    Department-by-department cutover

    Pick the office with the most pain. Sponsored Programs and Financial Aid are common first choices. Move that office's workflow, then repeat on a schedule the campus controls. Each cutover is independent.

    Sequenced to your priorities, one department at a time.

  3. 3

    Sunset, optional

    Some campuses retire the incumbent ECM once active workflows have moved; others keep it as a read-only archive. Either way, the Feith vault holds the authoritative copy of anything still in flight.

    When the campus is ready. The decision is reversible.

Institutional

Forty-seven years of federal records work, now in your registrar's office.

A state university CIO doesn't have to argue the architecture from first principles. The vault, audit log, identity layer, and lifecycle services under the platform are the same components that align to the National Archives' Universal ERM requirements and are built to the Department of Defense's records standard.

  1. 1979
    Feith Systems founded in Fort Washington, PA, with federal records from day one.
  2. 2002
    DoD 5015.02-STD certification achieved through DISA-JITC, renewed continuously until the standard was retired in 2023, now DoDM 8180.01.
  3. 2025
    USDA-sponsored FedRAMP Moderate authorization.
Talk to Feith

Bring the records architecture to your campus.

A walkthrough of your actual records workflow, showing what Feith does in the office with the most pain.

On the call
  • Your records workflow walked through, office by office, against FERPA and the rest of your compliance stack.
  • How FERPA, NIST 800-171, state public records, and Title IX apply to your stack.
  • A pricing range built on your member population — the people whose records are under management — with perpetual and subscription options.
Book a walkthrough
Available through
GSA MAS
Request pricing ›